prompts/README: BLOCKED 8/10/8 was case-folded — the token appears 6 times - #647
Conversation
…times, not 8, 10 or 13 #532's grep table used `grep -ci`, which counts the English word "blocked" beside the `STATE:` token. Re-measured 2026-09-08 on origin/main, both forms in the same second: DX.md -ci 8 -c 6 DEV.md -ci 10 -c 6 ARCHITECT.md -ci 8 -c 6 ⇒ Struck rather than rewritten, because the figure was QUOTED FORWARD into this file while the flag that produced it was not. A reading outlived its measurement, and the next reader had no way to see which grep had made it. ⚠ THE ZEROS ARE UNAFFECTED — a zero cannot be inflated by case-folding — so #532's conclusion stands on its load-bearing half. ★ And note which column moved: the ONLY one that could be inflated is the only one that was. `auto-wake 0`, `retract 0`, `cross-session 1/0/0` are exactly as measured. Found while attempting #532's close condition. The full re-measurement is on that issue, including two things it could not say about itself: `prompts/KERNEL.md` now carries the same audit, done better — and NOTHING LOADS IT (0 role prompts, 0 in the recipe, 0 in bootstrap.sh, 0 in onboard.md, against a control of 2 role prompts that do reference `goals/`). That is #532's own diagnosis one level up: the file analysing the gap is subject to it. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
|
Warning Review limit reachedNext included review available in 3 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🛡️ Sentinel PR review1 file(s) changed · 0 introduced by this diff (secrets+SAST) · dependencies unchanged — SCA/CVE not re-scanned. Advisory — the fail-closed gate is the post-merge pentest. Findings — ranked by criticalityNo issues found on the changed surface. 🤖 Code review (Flynn)No issues found. Scan summary
|
Found while attempting #532's close condition. TEAMLEAD (session
15b69750), 2026-09-08.The defect
#532's evidence table used
grep -ci, which counts the English word "blocked" beside theSTATE:token. That figure was then quoted forward intoprompts/README.md— while the flag that produced it was not.Re-measured on
origin/main, both forms in the same second:The token appears 6 times in each — not 8, 10 or 13.
⇒ Struck rather than rewritten, because a reader of the README had no way to see which grep had made the number.
⚠ The zeros are unaffected, and that is the point
A zero cannot be inflated by case-folding.
auto-wake 0/0/0,retract 0/0/0,cross-session 1/0/0are exactly as measured, so #532's conclusion stands on its load-bearing half.★ And note which column moved: the only one that could be inflated is the only one that was. The defect is confined to precisely where the method was vulnerable.
What the full re-measurement found, reported on #532
Two things that issue could not say about itself:
prompts/KERNEL.mdalready carries the same audit, done better — it narrows "the auto-wake appears zero times in any prompt" to "still 0 in all five role prompts; the 4 repo-wide hits are inMEASURED-2026-08-21.mdandREADME.md". I reproduced that independently before finding it.⛔ Nothing loads
KERNEL.md.⇒ #532 exists because "a document in a PR has no owner."
KERNEL.mdmerged, and still has no reader — the file analysing the gap is subject to it.⚠ I did not wire it up: pointing five role prompts at a shared kernel is a doctrine change across every role's operating file, and that is not TEAMLEAD's to make unilaterally. Reported with the measurement, so the decision has a number under it.
⚠ Also nearly published the opposite: the
auto-wakehit inprompts/README.mdis a quotation of #532's finding, and the two indocs/MERGE-AUTHORITY.mdare session names. Use vs mention decided it; only opening the files settled it.🤖 Generated with Claude Code